IoT Application Authorization via Pre-Authenticated Network Contexts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current interfaces between IoT devices and networks lack scalable mechanisms for authentication and authorization, leading to communication delays and inefficiencies between IoT devices, content providers, and network operators.
Innovation Solution
A method and apparatus for IoT device authentication and authorization that involves receiving a device authorization request with application-specific information, identifying the application, checking its authorization status, and transmitting an authorization approval containing application-specific information, facilitating efficient information transfer and reducing the need for repeated authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If current interfaces between IoT devices and networks are used for authentication and authorization, then device security is maintained, but communication delays increase and efficiency decreases
Solution Approach 1:
The patent implements preliminary action by establishing authentication and authorization contexts before actual communication occurs. The network operator's network authentication function authenticates the IoT device and establishes an authentication context, while the content provider's authentication function simultaneously authorizes the device for specific content services. This preliminary authentication and authorization setup eliminates the need for repeated authentication checks during subsequent communications, thereby reducing communication delays and improving efficiency.
Solution Approach 2:
The patent introduces intermediary authentication functions as mediators between IoT devices, network operators, and content providers. The network authentication function acts as an intermediary that handles device authentication, while the content provider authentication function serves as an intermediary for authorization decisions. These intermediary functions streamline the authentication and authorization process by centralizing the verification logic, reducing the overhead of repeated authentication checks, and enabling faster communication between all parties.
2Ease of manufacture
If traditional authentication mechanisms are used, then security is maintained, but operating expenses increase
Solution Approach 1:
The patent applies universality by designing a multi-functional authentication system where the network authentication function performs both device authentication and authorization coordination, while the content provider authentication function handles both authorization verification and session management. This universal approach consolidates multiple authentication-related operations into single functions, reducing the number of separate systems needed and thereby lowering operating expenses while maintaining security through comprehensive authentication coverage.
Solution Approach 2:
The patent implements self-service by enabling the authentication and authorization system to automatically manage its own operations. The authentication functions automatically verify device credentials, establish authentication contexts, and coordinate authorization decisions without requiring manual intervention. The system self-manages authentication state information and automatically handles subsequent communications, reducing operational overhead and expenses while maintaining reliable security through automated verification processes.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
A method and apparatus for device authentication and authorisation, wherein the method comprises: receiving, at an authentication and authorisation node, a device authorisation request comprising identity information for an application executed by a device and a first application specific container containing application specific information; identifying, using the device authorisation request, the application to which the request relates, and checking the authorisation status of the application; if the application is authorised for use, transmitting an authorisation approval, the authorisation approval comprising the first application specific container containing application specific information.